What changed in AI security, Oct 6 to Oct 12, 2025
Oct 6 to Oct 12, 2025 (ISO week 2025-W41). Weeks run Monday to Sunday in UTC.
19 records published, +3 on the previous week: 12 vulnerabilities (+2), 0 incidents (no change), 7 research items (+2), 0 news items (-1), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- Critical
CVE-2025-59286: Copilot command injection allows unauthorized information disclosure
CVE-2025-59286NVD/CVE Database - Critical
CVE-2025-59272: Copilot command injection allows local information disclosure
CVE-2025-59272NVD/CVE Database - Critical
CVE-2025-59252: Copilot command injection allows unauthorized information disclosure
CVE-2025-59252NVD/CVE Database - Critical
CVE-2025-61913: Flowise path traversal in WriteFileTool and ReadFileTool allows
CVE-2025-61913NVD/CVE Database - High
CVE-2025-6242: vLLM SSRF in MediaConnector via load_from_url methods
CVE-2025-6242NVD/CVE Database - High
CVE-2025-61784: LLaMA-Factory SSRF and file inclusion via chat API image URLs
CVE-2025-61784NVD/CVE Database - High
CVE-2025-59425: vLLM API key validation vulnerable to timing attack
CVE-2025-59425NVD/CVE Database - High
CVE-2025-6985: HTMLSectionSplitter in langchain-text-splitters XXE via unsafe XSLT parsing
CVE-2025-6985NVD/CVE Database - High
CVE-2025-61687: Flowise arbitrary file upload allowing persistent web shell storage
CVE-2025-61687NVD/CVE Database - Critical
CVE-2025-59159: SillyTavern web user interface DNS rebinding
CVE-2025-59159NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2025-61913: Flowise path traversal in WriteFileTool and ReadFileTool allows CVE-2025-61913NVD/CVE Database | Not listed | 13.0% | |
| CVE-2025-61687: Flowise arbitrary file upload allowing persistent web shell storage CVE-2025-61687NVD/CVE Database | Not listed | 11.0% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| optimum-onnx | PyPI | Hugging Face Hub / Transformers | 0.0.1 | |
| jupyter-ai-litellm | PyPI | LiteLLM | 0.0.1 | |
| langchain-classic | PyPI | LangChain | 1.0.0a1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Coding assistants | 3 | 0.3 | +2.8 |
Research
Peer-reviewed first, then newest.Exploring Energy Landscapes for Minimal Counterfactual Explanations: Applications in Cybersecurity and Beyond
Peer-reviewedIEEE Xplore (Security & AI Journals)FGRW: Fine-Grained Reversible Watermarking Based on Distribution-Adaptive Contrastive Augmentation Across Diverse Domains
Peer-reviewedIEEE Xplore (Security & AI Journals)Octopus: A Robust and Privacy-Preserving Scheme for Compressed Gradients in Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Model Stability Defense Against Model Poisoning in Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Revealing the Risk of Hyper-Parameter Leakage in Deep Reinforcement Learning Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Syntax-Oriented Shortcut: A Syntax Level Perturbing Algorithm for Preventing Text Data From Being Learned
Peer-reviewedIEEE Xplore (Security & AI Journals)Hard Sample Mining: A New Paradigm of Efficient and Robust Model Training
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.